Hi EMS/FGT admins
When creating ZTNA proxy rule (in Policy & Object > Proxy Policy) for clients that are off-fabric, is there anything valid that we can put in "Source" field other than "all"?
Trying to put the public source address of the client, or even the client's private source address behind its router, but nothing seem to match, only "all" works. It seems srcaddr in ZTNA proxy rules means something different than in standard rules, but can't find what.
Any idea?
Hi,
Can you share the snapshot of the proxy policy setup for better clarity
setting up private IP should work as in the wad debug you will see the traffic coming with the private PC ip
Hi Joshi
Thanks for your response.
Here is the screenshot:
On the tech tip you shared, they are also using "all" as source address in the ZTNA rule.
User | Count |
---|---|
2061 | |
1175 | |
770 | |
448 | |
343 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.